Final beta release of the Snort 3 attack detection system

Cisco introduced the final beta version of the completely revamped attack prevention system Snort 3, also known as the Snort++ project, which has been in development since 2005 with some interruptions. A release candidate is expected to be published later this year.

The new branch fully rethinks the product concept and reworks the architecture. The key focus areas for this new branch include simplifying the setup and launch of Snort, automating configuration, simplifying the rule-building language, automatically detecting all protocols, providing a command-line management shell, and actively utilizing multithreading with shared access for different handlers to a single configuration.

The following significant innovations have been implemented:

  • A transition to a new configuration system has been made, offering simplified syntax and allowing the use of scripts for dynamic configuration. LuaJIT is employed for processing configuration files. LuaJIT-based plugins provide additional options for rules and the logging system;
  • The attack detection engine has been modernized, rules have been updated, and the ability to bind buffers in rules (sticky buffers) has been added. The Hyperscan engine has been utilized, allowing for the use of fast and more accurate pattern matching based on regular expressions in rules;
  • A new HTTP introspection mode has been introduced, taking session state into account and covering 99% of situations supported by the test set HTTP Evader. Code for HTTP/2 support is in development;
  • Significant performance improvements have been made in the deep packet inspection mode. Multithreaded packet processing has been enabled, allowing multiple threads with packet handlers to execute simultaneously and providing linear scalability based on the number of CPU cores;
  • A unified configuration storage and attribute tables have been implemented, which are shared across different subsystems, significantly reducing memory consumption by eliminating information duplication;
  • A new event logging system using JSON format that easily integrates with external platforms such as Elastic Stack;
  • Transition to modular architecture, enabling functionality expansion through plugin connections and implementation of key subsystems as replaceable plugins. Currently, several hundred plugins have been developed for Snort 3, covering various use cases, such as allowing the addition of custom codecs, introspection modes, logging methods, actions, and options in rules;
  • Automatic detection of active services, eliminating the need for manual specification of active network ports.

Changes compared to the previous testing release published in 2018:

  • Support for files for quick configuration overrides relative to the default settings;
  • Enabled support for C++ constructs defined in the C++14 standard (requires a compiler that supports C++14 for building);
  • A new VXLAN handler has been added;
  • Improved content type searching by content using updated alternative implementations of algorithms Boyer-Moore and Hyperscan;
  • The HTTP/2 traffic inspection system is nearly fully ready;
  • Startup accelerated by utilizing multiple threads for compiling rule groups;
  • A new logging mechanism has been added;
  • Improved Lua error detection and optimized whitelists operation;
  • Changes made to implement on-the-fly configuration reloads;
  • Introduced a Real-time Network Awareness (RNA) inspection system that gathers information about available resources, hosts, applications, and services in the network;
  • For simplification, the use of snort_config.lua and SNORT_LUA_PATH has been discontinued.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster